US2020167766A1PendingUtilityA1

Security and authentication of interaction data

Assignee: MASTERCARD INTERNATIONAL INCPriority: Nov 28, 2018Filed: Nov 25, 2019Published: May 28, 2020
Est. expiryNov 28, 2038(~12.3 yrs left)· nominal 20-yr term from priority
G06Q 20/08G06Q 20/382H04W 12/06H04L 63/0272H04W 88/16H04L 63/08G06Q 20/3227
58
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

There is provided a computer-implemented method of authenticating an interaction carried out between a mobile device and a gateway, the method being carried out by an authentication system remote from the mobile device and the gateway. The method comprises the steps of: receiving one or more first data items from the gateway, the one or more first data items including dynamic data corresponding to one or more second data items uniquely identifying the interaction, wherein one of the second data items corresponds to a portion of a counter value associated with the interaction; and extracting the counter value portion from the dynamic data. The method further comprises calculating one or more candidate counter values which could correspond to the counter value associated with the interaction; generating, for each of the one or more candidate counter values, a piece of corresponding candidate dynamic data based on one or more of the other first data items; and comparing each of the candidate dynamic data to the received dynamic data to ascertain whether a match is obtained.

Claims

exact text as granted — not AI-modified
1 . A computer-implemented method of authenticating an interaction carried out between a mobile device and a gateway, the method being carried out by an authentication system remote from the mobile device and the gateway, the method comprising the steps of:
 receiving one or more first data items from the gateway, the one or more first data items including dynamic data corresponding to one or more second data items uniquely identifying the interaction, wherein one of the second data items corresponds to a portion of a counter value associated with the interaction;   extracting the counter value portion from the dynamic data;   calculating one or more candidate counter values which could correspond to the counter value associated with the interaction;   generating, for each of the one or more candidate counter values, a piece of corresponding candidate dynamic data based on one or more of the other first data items; and   comparing each of the candidate dynamic data to the received dynamic data to ascertain whether a match is obtained.   
     
     
         2 . The method of  claim 1 , further comprising retrieving, from an associated memory of the remote system, a range of possible counter values for use in the calculating step. 
     
     
         3 . The method of  claim 2 , wherein the calculating step is carried out in dependence on a correspondence between the extracted counter value portion and the retrieved range of possible counter values. 
     
     
         4 . The method of  claim 2 , further comprising updating the stored range of possible counter values based on the candidate counter value used to generate the candidate dynamic data for which a match with the received dynamic data is obtained. 
     
     
         5 . The method of  claim 3 , further comprising updating the stored range of possible counter values based on the candidate counter value used to generate the candidate dynamic data for which a match with the received dynamic data is obtained 
     
     
         6 . The method of  claim 1 , wherein the received dynamic data is encrypted, wherein each of the candidate dynamic data pieces comprises a dynamic cryptogram encrypted using a cryptographic key, the cryptographic key being selected based on the corresponding candidate counter value. 
     
     
         7 . The method of  claim 2 , wherein the received dynamic data is encrypted, wherein each of the candidate dynamic data pieces comprises a dynamic cryptogram encrypted using a cryptographic key, the cryptographic key being selected based on the corresponding candidate counter value. 
     
     
         8 . The method of  claim 3 , wherein the received dynamic data is encrypted, wherein each of the candidate dynamic data pieces comprises a dynamic cryptogram encrypted using a cryptographic key, the cryptographic key being selected based on the corresponding candidate counter value. 
     
     
         9 . The method of  claim 4 , wherein the received dynamic data is encrypted, wherein each of the candidate dynamic data pieces comprises a dynamic cryptogram encrypted using a cryptographic key, the cryptographic key being selected based on the corresponding candidate counter value. 
     
     
         10 . The method of  claim 5 , wherein the received dynamic data is encrypted, wherein each of the candidate dynamic data pieces comprises a dynamic cryptogram encrypted using a cryptographic key, the cryptographic key being selected based on the corresponding candidate counter value. 
     
     
         11 . A computer-implemented method of generating data for authentication of an interaction carried out between a mobile device and a gateway, the method comprising the steps of:
 generating, at the mobile device, one or more first data items corresponding to properties of the interaction, and one or more second data items uniquely identifying the interaction;   generating, at the mobile device, dynamic data based on one or more of the second data items;   altering, at the mobile device, one or more of the first data items using a portion of the dynamic data; and   transmitting, from the mobile device via the gateway, the altered one or more first data items to a remote system for authentication.   
     
     
         12 . The method of  claim 11 , wherein one of the second data items comprises a counter value associated with the interaction, and further wherein generating the dynamic data comprises generating dynamic cryptographic data using the counter value. 
     
     
         13 . The method of  claim 11 , wherein the interaction comprises an online payment transaction, and the gateway corresponds to an online payment gateway associated with a merchant. 
     
     
         14 . The method of  claim 12 , wherein the interaction comprises an online payment transaction, and the gateway corresponds to an online payment gateway associated with a merchant 
     
     
         15 . The method of  claim 13 , wherein the one or more first data items comprise an expiry date of a payment card used in the payment transaction, and wherein the altering step comprises replacing the expiry date with a portion of the dynamic data. 
     
     
         16 . The method of  claim 14 , wherein the one or more first data items comprise an expiry date of a payment card used in the payment transaction, and wherein the altering step comprises replacing the expiry date with a portion of the dynamic data. 
     
     
         17 . The method of  claim 13 , wherein the one or more first data items comprise cryptographic data identifying a payment card used in the payment transaction, and wherein the altering step comprising replacing at least a part of the cryptographic data with a portion of the dynamic data. 
     
     
         18 . The method of  claim 15 , wherein the one or more first data items comprise cryptographic data identifying a payment card used in the payment transaction, and wherein the altering step comprising replacing at least a part of the cryptographic data with a portion of the dynamic data. 
     
     
         19 . The method of  claim 16 , wherein the one or more first data items comprise cryptographic data identifying a payment card used in the payment transaction, and wherein the altering step comprising replacing at least a part of the cryptographic data with a portion of the dynamic data. 
     
     
         20 . A computer program product comprising instructions which, when the program is executed by a computer, cause the computer to carry out the steps of:
 receiving one or more first data items from the gateway, the one or more first data items including dynamic data corresponding to one or more second data items uniquely identifying the interaction, wherein one of the second data items corresponds to a portion of a counter value associated with the interaction;   extracting the counter value portion from the dynamic data;   calculating one or more candidate counter values which could correspond to the counter value associated with the interaction;   generating, for each of the one or more candidate counter values, a piece of corresponding candidate dynamic data based on one or more of the other first data items; and   
       comparing each of the candidate dynamic data to the received dynamic data to ascertain whether a match is obtained.

Join the waitlist — get patent alerts

Track US2020167766A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.